News: 1713875415

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UnitedHealth admits breach could 'cover substantial proportion of people in America'

(2024/04/23)


UnitedHealth Group, the parent of ransomware-struck Change Healthcare, delivered some very unwelcome news for customers today as it continues to recover from the massively expensive side and disruptive digital break-in.

"Based on the initial targeted data sampling to date, the company has found files containing protected health information and personally identifiable information, which could cover a substantial proportion of people in America," it [1]said in a statement.

"To date, the company has not seen evidence of exfiltration of materials such as doctors' charts or full medical histories among the data," UnitedHealth added.

[2]

The ransomware attack, which [3]began in February , impacted hospital and pharmacies that use the insurance and billing services of UnitedHeath across the US for weeks. Electronic prescriptions came [4]back online in early March .

[5]

[6]

The exact number of people affected was not mentioned. Given the "ongoing nature and complexity of the data review," the insurance giant estimates it will likely take third party experts "several months of continued analysis" to comb through enough information to "identify and notify impacted customers and individuals."

An affiliate of [7]ALPHV claimed responsibility for the breach. According to a report in the [8]Wall Street Journal yesterday, the criminal crew got into Change Healthcare's network via pilfered credentials for a tech system that permits remote access to its network. The criminal gang spent more than a week inside until they unleashed the ransomware and stole data from the systems.

[9]

A spokesperson at UnitedHealth told [10]TechCrunch that a ransom had been paid "as part of the company's commitment to do all it could to protect patient data from disclosure." The amount was not specified but it was understood to be around [11]$22 million .

RansomHub, another criminal crew, [12]recently released what is believed to be personal patient data from the hack and itself demanded a ransom to stop it leaking more. It claimed that it was storing the data, and not ALPHV.

[13]185K people's sensitive data in the pits after ransomware raid on Cherry Health

[14]Change Healthcare faces second ransomware dilemma weeks after ALPHV attack

[15]White House and lawmakers increase pressure on UnitedHealth to ease providers' pain

[16]Change Healthcare registers pulse after crippling ransomware attack

UnitedHealth and its external cyber specialists claim they are still "monitoring" the dark web to ascertain if more data has been published online. The company says it saw 22 screenshots, "allegedly from exfiltrated files," some of which contained protected health information and personally identifiable information, that it says was posted on the dark web for roughly one week by miscreants, but claims it has spotted nothing since.

The cost of the saga to the org is currently pegged at [17]$870 million for calendar Q1 and could stretch to $1.6 billion for the year, UnitedHealth confirmed last week. ®

Get our [18]Tech Resources



[1] https://www.unitedhealthgroup.com/newsroom/2024/2024-04-22-uhg-updates-on-change-healthcare-cyberattack.html

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZifbIokOFE-d7Tbaotn5MgAAAJA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2024/02/22/change_healthcare_outage/

[4] https://www.theregister.com/2024/03/08/change_healthcare_restores_first_system/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZifbIokOFE-d7Tbaotn5MgAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZifbIokOFE-d7Tbaotn5MgAAAJA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2024/02/29/alphv_change_healthcare/

[8] https://www.wsj.com/articles/change-healthcare-hackers-broke-in-nine-days-before-ransomware-attack-7119fdc6

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZifbIokOFE-d7Tbaotn5MgAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://techcrunch.com/2024/04/22/unitedhealth-change-healthcare-hackers-substantial-proportion-americans/

[11] https://www.theregister.com/2024/03/04/alphv_ransom_payment/

[12] https://www.theregister.com/2024/04/08/change_healthcare_ransomware/

[13] https://www.theregister.com/2024/04/18/ransomware_cherry_health/

[14] https://www.theregister.com/2024/04/08/change_healthcare_ransomware/

[15] https://www.theregister.com/2024/03/12/white_house_pressures_unitedhealth/

[16] https://www.theregister.com/2024/03/08/change_healthcare_restores_first_system/

[17] https://www.theregister.com/2024/04/16/change_healthcares_ransomware_attack_has/

[18] https://whitepapers.theregister.com/



What about one-time credentials?

Mike 137

" the criminal crew got into Change Healthcare's network via pilfered credentials for a tech system that permits remote access to its network "

As a really basic protection, any remote access for technical management should always use connection source validation and out of band generated one-time credentials so they're useless to an adversary. This is so fundamental! It amazes me that any business fails to implement it. Unless of course this breach really resulted from compromise of an already authenticated current session, which is a whole different issue. And then of course there's the question of whether the network segregation was adequate.

But as Major General Jonathan Shaw, late head of cyber security at the UK MoD famously stated “ ...about 80 per cent of our cyber problems are caused by what I call poor cyber hygiene. ”

Korev

The cost of the saga to the org is currently pegged at $870 million for calendar Q1 and could stretch to $1.6 billion for the year, UnitedHealth confirmed last week. ®

I'd love to know if Change Healthcare's geeks had tried to get and were turned down for money to bring the company's infrastructure up to date. If that is the case, then I'd like to know even more if the sum requested was less than $870M

Doctor Syntax

They may have proposed procedures which could have involved trading a smidge of inconvenience for security. Nothing like the inconvenience caused to all the victims, of course.

blackmailed twice

Valeyard

Pay the ransom then the blackmailers return for a double dip.

well I never.

Doctor Syntax

Things are at least improving about the PR response. It's not claimed to be just a few.

There is no such thing as fortune. Try again.